• Sources: primary, discussion
  • Summary: The post is Anil Madhavapeddy's first-hand account of his own cohttp 6.3.0 security fix, and it reports exploit probes arriving about ten minutes after the fix was opened publicly. It cites a mean time to exploit of minus seven days, a figure taken from a Vulncheck chart that this run could read only as the post's prose. The post is dated 2026-08-22 and reached Hacker News on 2026-08-28, and it names 6.3.0 only as the release carrying the fix, so the affected cohttp version range and a CVE identifier are not established by the source.
  • Why it matters: If a rough description of a bug class is enough for an agent to produce a working exploit, the embargo model that open source security response rests on no longer buys maintainers time.

send feedback on this story